| Ãë¾àÁ¡ID |
12032 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
|
| ÇÁ·ÎÅäÄÝ |
UDP |
| ºÐ·ù |
RPC |
| »ó¼¼¼³¸í |
ÇØ´ç RPC ¼ºñ½º 100009 (yppasswdd)´Â ¿ø°ÝÀ¸·Î root ½©À» ȹµæÇÒ ¼ö ÀÖ´Â Buffer Overflow¿¡ Ãë¾àÇÏ´Ù. rpc.yppasswdd ¼¹ö´Â yppasswd ¸í·É¿¡ ÀÇÇÑ ÆÐ½º¿öµå º¯°æ ¿äûµéÀ» ó¸®Çϰí NIS ÆÐ½º¿öµå ÆÄÀÏÀ» ¼öÁ¤Çϴµ¥ »ç¿ëµÈ´Ù. SPARC ±â¹ÝÀÇ Ç÷§Æû¿¡ ´ëÇÑ Buffer Overflow Ãë¾àÁ¡Àº Solaris 2.6, 7 ±×¸®°í 8 ¸Ó½Åµé¿¡ ÀÖ´Â 'yppassword' ¼ºñ½º¿¡¼ ¹ß°ßµÇ¾ú´Ù. Solaris 2.6, 7 ±×¸®°í 8ÀÇ Intel/x86 ¹öÀüµµ ¶ÇÇÑ Ãë¾àÁ¡ÀÌ ÀÖÀ» ¼ö ÀÖ´Ù. ±× µ¥¸óÀº superuser ·Î½á ¼öÇàµÇ¹Ç·Î ·ÎÄà ȤÀº ¿ø°Ý¿¡¼ÀÇ »ç¿ëÀÚµéÀÌ ¿ÏÀüÇÑ ½Ã½ºÅÛ ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ ³»ÀÇ ÀÓÀÇÀÇ ¸í·ÉÀÇ ¼öÇàÀÌ °¡´ÉÇÏ´Ù.
* °æ°í: ÀÌ ¼ºñ½º´Â ¹öÆÛ ¿À¹öÇ÷οì Å×½ºÆ®¿¡ ÀÇÇØ Å©·¡½¬ µÇ¾úÀ» °ÍÀ̹ǷÎ, ±â´ÉÀ» Á¤»óÀ¸·Î ȸº¹Çϱâ À§Çؼ´Â ¼ºñ½º¸¦ Àç½ÃÀÛÇÏ¿©¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/2763 http://www.iss.net/security_center/static/6629.php
* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû: Caldera OpenServer 5.0.5 Caldera OpenServer 5.0.6 Solaris 2.6 Solaris 7 Solaris 8 |
| ÇØ°áÃ¥ |
»ç¿ëÇÏÁö ¾Ê´Â´Ù¸é ÀÌ ¼ºñ½º¸¦ Disable ½ÃÄÑ¾ß ÇÑ´Ù. ÀÌ ¼ºñ½ºÀÇ °¡µ¿À» ÁßÁöÇϱâ À§Çؼ´Â:
/usr/lib/netsvc/yp/ypstart ÆÄÀÏÀÇ 133 ¶óÀÎ ±Ùó¿¡¼ ´ÙÀ½°ú °°Àº ½ºÅ©¸³Æ®¸¦ ¹ß°ßÇÒ ¼ö ÀÖ´Ù. [$YPDIR/rpc.yppasswdd $PWDIR -m && echo 'rpc.yppasswdd\c'] ±× ¶óÀÎÀ» ÁÖ¼®Ã³¸®Çϰí /usr/lib/netsvc/yp/ypstop ¿Í ypstart ¸í·ÉÀ» Â÷·Ê´ë·Î ¼öÇà½ÃŲ´Ù. NIS°¡ ¼öÇàµÇ°í ÀÖ´Â »óÅ¿¡¼µµ yppassword¸¦ ÀÛµ¿ÁßÁö ½Ã۸é ÇØÅ·Àº ÀϾÁö ¾Ê´Â´Ù. ±×·¯³ª ÀÌ·¸°Ô Çϸé yppassword°¡ ÀÛµ¿ÇÏÁö ¾ÊÀ¸¹Ç·Î »ç¿ëÀÚµéÀº ÀڽŵéÀÇ ÆÐ½º¿öµåÀÇ º¯°æÀÌ ºÒ°¡´ÉÇÏ°Ô µÈ´Ù.
-- ȤÀº --
½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡³ª ¾÷±×·¹À̵带 ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù.
Sun SolarisÀÇ °æ¿ì: Oracle »ç¿¡ ¹®ÀÇÇÏ¿© ÇØ´ç ½Ã½ºÅÛÀÇ ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ´Ù.
Solaris 2.6: 106303-03 Solaris 2.6_x86: 106304-03 Solaris 7: 111590-02 Solaris 7_x86: 111591-02 Solaris 8: 109320-01 Solaris 8_x86: 111597-02
Caldera OpenServer 5.0.5¿Í 5.0.6ÀÇ °æ¿ì: ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© OpenServer 5.0.7 ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù. http://www.sco.com/support/download.html
±âŸ: °¢ º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡¸¦ ±¸ÇÏ¿© Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2001-0779 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|